Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A SysOps administrator needs to monitor Amazon S3 for object-level operations such as PUT and DELETE events in a specific bucket. The administrator wants these events to be sent to an Amazon SQS queue for downstream processing by an application. Which solution should be used to achieve this with the least operational overhead?

⚠ Common exam trap

The trap here is that candidates may overcomplicate the solution by choosing CloudTrail or Lambda-based approaches, forgetting that S3 has a built-in, direct event notification feature for SQS that requires no additional services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an S3 event notification on the bucket to send events to an SQS queue.

Amazon S3 can directly publish event notifications for object-level operations (e.g., PUT, DELETE) to an SQS queue without any intermediate services. This native integration requires no custom code or additional infrastructure, minimizing operational overhead while meeting the requirement to send events to SQS for downstream processing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Amazon CloudWatch Events to match S3 API calls from CloudTrail and route to an SQS queue.

    Why it's wrong here

    Amazon CloudWatch Events (now EventBridge) can match S3 API calls logged by CloudTrail, but CloudTrail logs are delivered on an asynchronous, batched basis—typically 5–15 minutes after the API call—so the event stream is not near-real-time. You would also need to build a rule with an event pattern and a target to SQS, which adds unnecessary infrastructure compared to the native S3 event notification. Since S3 already publishes lifecycle events (e.g., s3:ObjectCreated:*) directly to SQS within seconds, relying on CloudTrail as a proxy introduces avoidable latency and operational complexity.

  • ✓

    Configure an S3 event notification on the bucket to send events to an SQS queue.

    Why this is correct

    S3 bucket event notifications natively publish a rich event envelope (bucket, object key, size, etag) to a designated SQS queue as soon as the object operation completes, making them the most direct, low-latency mechanism for this requirement. The integration is fully managed: you enable the notification in the bucket configuration, attach an SQS resource policy that allows S3 to send messages, and S3 handles retries and batching automatically. This eliminates the need for custom intermediaries or polling, and supports prefix/suffix filters so the queue only receives relevant object events.

  • ✗

    Deploy an application that periodically polls S3 for changes using ListObjects.

    Why it's wrong here

    Polling for changes with ListObjects (or ListObjectsV2) requires continuously comparing snapshots of the bucket to infer what changed, but the API returns only a current listing—it does not produce an event or identify which object changed between calls. Each comparison cycle needs to store state from the previous scan, and frequent polling of large buckets generates massive request costs, throttling risk, and delayed detection. This approach is inherently non-event-driven and scales poorly compared to S3's push-based notification to SQS.

  • ✗

    Use AWS CloudTrail to deliver logs to CloudWatch Logs, then create a metric filter and trigger a Lambda function to send to SQS.

    Why it's wrong here

    This pipeline uses CloudTrail logs, which are delivered to CloudWatch Logs only after a significant delay and for data events can be sparse if not explicitly enabled. A metric filter merely counts log occurrences; it does not extract the full event payload, so you would need a Lambda function to parse the JSON and reconstruct the object key—adding brittle custom code. Even after those hops, the end-to-end latency is dominated by CloudTrail and Logs ingestion, so it cannot match the sub-second to few-second delivery of a direct S3 event notification to SQS.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.